hacker-news · Crawled Oct 1, 2026

OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted

1 CVEs
Read original article ↗

AI Summary

OpenSSL has addressed a high-severity vulnerability, CVE-2026-84782, affecting DTLS implementations that can lead to heap memory leakage in unencrypted handshake data or cause a program crash. The flaw occurs when a DTLS handshake message is resent while a larger message is partially sent, resulting in the use of incorrect buffer positioning and potential exposure of sensitive memory contents. The vulnerability impacts multiple OpenSSL branches, with public fixes available for newer versions and only premium support customers receiving updates for older versions like 3.0, 1.1.1, and 1.0.2.

AI-extracted · verify before operational use

Extracted Entities 1 found